Blocking Compromised Passwords on PyPI
caremad.io
caremad.io
There should be no harm in doing it, and the admin would get a new switch "check the password with HIBP at login time (Y/n)". This could have a good impact - and it could be done from either client or server-side.
EDIT: after checking, it's already in Nextcloud: [0] https://github.com/nextcloud/password_policy/commit/fed9c37f...
I maintain an add-on for Django that does this, for example, but I can't force people to go and use it, though I also maintain one of the more popular user-registration apps and I probably will find a way to enable it by default in there.
>ESLint
Glass houses. SSH Decorator was much worse, it stole SSH keys.